feat(integration): add durable plugin delivery attempt admission - #252
seonghobae wants to merge 73 commits into
Conversation
📝 WalkthroughWalkthrough플러그인 전달 시도 admission 기능을 추가했습니다. 애플리케이션은 활성 grant와 요청 데이터를 검증합니다. PostgreSQL 저장소는 멱등 삽입과 충돌 재조회를 수행합니다. 마이그레이션은 권한과 상태 제약조건을 적용합니다. CI는 focused 및 전체 테스트를 실행합니다. Changes플러그인 전달 시도 입장
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant Caller
participant PluginDeliveryAttemptApplication
participant PluginDeliveryAttemptOriginReader
participant PostgresPluginDeliveryAttemptStore
participant PostgreSQL
Caller->>PluginDeliveryAttemptApplication: schedule(context, input)
PluginDeliveryAttemptApplication->>PluginDeliveryAttemptOriginReader: getGrant(...)
PluginDeliveryAttemptOriginReader-->>PluginDeliveryAttemptApplication: active grant
PluginDeliveryAttemptApplication->>PostgresPluginDeliveryAttemptStore: createIfAbsent(candidate)
PostgresPluginDeliveryAttemptStore->>PostgreSQL: parameterized insert
PostgreSQL-->>PostgresPluginDeliveryAttemptStore: inserted or conflict
PostgresPluginDeliveryAttemptStore-->>PluginDeliveryAttemptApplication: durable winner
PluginDeliveryAttemptApplication-->>Caller: pending attempt or authority error
Merge Risk: 🟡 Moderate · up to Dependency failures can escape the admission contract, a misconfigured test run can delete Integration data, and deferred attempts are persisted as immediately eligible. These issues should be fixed before merge. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 10.71% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 28 functions across 5 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh durable-evidence review found a second hostile SQL result-envelope gap after the earlier getter repair. |
|
Current exact authority correction — 2026-09-16 Current #252 head is Fresh source review first confirmed the durable-evidence repair at A fresh exact-head verifier exists for current Foundation order remains: exact #252 current-head terminal proof → purpose-verifier retirement → ordinary/non-force #253 parent adoption → descendant restack/revalidation. No force push, destructive rebase, source copy, or gate weakening. |
|
Current exact authority is Fresh Planning evidence exposed a shared harness defect in these bounded verifiers: New exact-head verifier |
|
Current exact authority (2026-09-16): head Two related hostile-object gaps were found after the earlier row-cardinality snapshot repair. First, Second, the application boundary used the same unbounded The purpose verifier was extended at |
seonghobae
left a comment
There was a problem hiding this comment.
Current exact authority — 2026-09-17.
Predecessor exact 3a81bae892164cef0f5639cfcb82bbbc955bdfdd run 35046845494 / job 104638403226 reached GitHub-hosted Ubuntu 24.04, completed exact checkout, Node 24 setup and frozen workspace install, then failed only Check focused formatting. The hostile row-collection regression, hostile application-authority regression and Integration typecheck were all skipped. Treat this as a formatting harness RED, not delivery-attempt product RED.
Current ordinary descendant is exact 039e5f9f0e61cdfd99bb17d8f79740b5ec3cdb23. Its only new source is a contents: read diagnostic workflow that applies repository Prettier to the same four verifier-owned files in the ephemeral runner worktree and prints the resulting diff; it has no push credential, no production/source mutation and no gate relaxation. Normal verifier 35225432463 and formatter diagnostic 35225432604 are both current-head non-terminal evidence.
Next valid transition is: consume only the exact diagnostic patch → remove the purpose-complete diagnostic by ordinary descendant → reacquire the unchanged normal verifier on that exact workflow-free source before any GREEN, child restack, merge or release claim.
seonghobae
left a comment
There was a problem hiding this comment.
Current exact authority — 2026-09-17.
The predecessor 35046845494 remains a formatting harness RED: exact checkout, Node and frozen install passed; focused Prettier failed before either hostile regression or Integration typecheck ran. A fresh cross-lane RCA on #258 also exposed the same verifier-selector defect present here: pnpm --filter @life-os/integration-service test -- <file> passes an unnecessary separator after a package script that already invokes Vitest, so it can enumerate the wider Integration suite rather than the named verifier file. This branch now passes each hostile file as the real positional argument without that extra separator.
Current exact 2a310040c2ee9ba11e12488c34c78c550476a8fe also hardens both normal and diagnostic checkout authority with ${{ github.sha }} and persist-credentials: false. The temporary formatter diagnostic is contents: read and now runs on every branch push so its diff belongs to the same exact head rather than an earlier diagnostic-only commit.
Current-head diagnostic 35225977578 and normal verifier 35225977580 are both queued/non-terminal. Valid next transition is exact diagnostic patch only → remove the purpose-complete diagnostic in an ordinary descendant → reacquire the unchanged normal verifier on that workflow-free exact. No GREEN, merge, or descendant restack before those exact results.
seonghobae
left a comment
There was a problem hiding this comment.
Current exact authority update — 2026-09-18.
Hosted formatter diagnostic 35225977578 completed SUCCESS on predecessor 2a310040c2ee9ba11e12488c34c78c550476a8fe. Its canonical Prettier patch touched only plugin-delivery-attempt-repository.ts, plugin-delivery-attempt-repository-hostile-collection.test.ts, and plugin-delivery-attempt.test.ts; plugin-delivery-attempt.ts was already canonical. Normal verifier 35225977580 on that predecessor failed only at focused formatting, before both hostile regressions and Integration typecheck.
The diagnostic output has now been applied verbatim by ordinary descendants and the purpose-complete diagnostic workflow removed. Current head is 5f5c118a6c82ccb35e57db203f19a1bad1c23c94; production semantics, migration/SQL authority, admission scope, retry budget, and egress boundary are unchanged. Fresh normal verifier run 35253757603 is queued on this exact head. Do not transfer predecessor GREEN or call the hostile row/application authority accepted until that exact verifier reaches the focused regressions and typecheck. Keep Draft; no merge or descendant restack from this lane before exact terminal evidence.
|
Fresh hosted evidence changed this lane. Exact The repair is therefore fixture-only, not a production catch-all. Ordinary descendants |
|
2026-09-18 current exact override: |
Current exact authority — 2026-09-19
Current exact head is
e67fa3de97cde2331e2ea771b6150b84c0d986b1, open / Draft / mergeable, directly based on #245 workflow-free exact39ebec99d907356a99a1a15528a3a1df713472ed.The latest row-collection hardening was revalidated on exact parent
e40fc9c60f122d7f3ed120075bfb07d273281711byVerify Plugin Delivery Attempt Row Collectionrun35280418160, which completed SUCCESS after exact checkout, Node 24 setup, frozen workspace install, focused formatting, hostile row-collection regression, hostile application-authority regression, and Integration typecheck. The ordinary descendante67fa3de...deletes only that purpose verifier; production source and retained regressions are unchanged from the proven exact head.The earlier verifier attempt
35029252125onf254e592...failed atSet up Node 24before any product regression ran, so it is infrastructure/harness evidence rather than a product RED. The subsequent exact GREEN above is the current bounded authority for this row-collection slice; it is not represented as protected-main merge or release authority.Buyer gap
Adds an Integration-owned durable plugin-delivery-attempt admission boundary directly on the #245 PostgreSQL runtime lane. It deliberately does not depend on mutable #250/#251 HTTP transport and does not grant outbound networking. Durable rows contain only opaque authority/lifecycle fields; provider payload, secret material, origin URI and network authorization remain outside this bounded context.
Database and domain invariant
Migration
0006_plugin_delivery_attempt_record.sqlcreates service-ownedplugin_delivery_attempt_recordwith UUIDv4 checks,pendingadmission status,attempt_count = 0, boundedmax_attempts, scheduling/timestamp constraints and scoped indexes. Its BEFORE INSERT trigger joins the exact active delivery-origin grant and owning active installation under matching workspace/user authority and acquiresFOR SHARE; missing or revoked authority fails closed with SQLSTATE 23514. No cross-service SQL or copied sibling persistence is introduced.The repository uses
INSERT ... ON CONFLICT DO NOTHING RETURNING; a zero-row idempotency conflict is followed by a fresh exact-scoped SELECT in a new PostgreSQL statement because Read Committed can suppress on a concurrent winner that is not visible to the same INSERT statement snapshot. Replay is accepted only when immutable admission scope matches.Preserved RED / repair authority
Regression-only
788873a413caa24fd4597d57dc29b4276d3f9ad9proves the application capability is absent before implementation. Regressiond9bf3384fc59219b2c8ebed4aa6360bd97c60460proves the concurrent idempotency-winner case requires a fresh statement snapshot. Hostile-envelope REDf47638672d005a5609764cec4a82ca7b3ef61c51→ repair912958fa1ee4541f851f203a2c1d7f41134d7449bounds Proxy/getter evidence before semantic validation.Dependency-rejection RED proof head
987f0a8ca1ffb132146eee784bf3a3f281801f58, run34202494161, job101984290407, failed exactly the two raw dependency-error cases while repository and real-PostgreSQL migration acceptance stayed GREEN. Minimum repairc6330c06b6372b2bcdbebf08b16e51a4339d300abounds onlyorigins.getGrant()andstore.createIfAbsent(). Exact run34203636724, job101987958062, completed GREEN on Ubuntu 24.04/PostgreSQL 16 across historical RED proofs, canonical formatting, diff hygiene, focused acceptance, Integration typecheck and the complete Integration suite.Fresh CodeRabbit review then produced four valid repair lines rather than waivers: distinct
requestedAt/updatedAt/nextAttemptAtpersistence (8ef43e...→5bfdee3...); destructive PostgreSQL target and explicit TLS policy (9f2d9b...→aca4c3.../da94bb...); bracketed IPv6 loopback (87b247...→f6ba35...); and table-level ownership/admission declaration (c77d0a...→171f15...). Exact proof head9e6e88e49e14d0b2d247e747df968e2494697666, run34209314512, job102006262067, completed GREEN across all four RED proofs, formatting/diff hygiene, focused delivery-attempt acceptance, Integration typecheck and the complete Integration suite. All four CodeRabbit threads are resolved. Workflow-retirement descendantcbb3caaddf3ad8d84ef27a6c7ba9aa624bed972aremoved only that purpose verifier.Hostile SQL durable-evidence repair
A later repository-boundary review found that
PostgresPluginDeliveryAttemptStoreread SQL result envelopes, durable row getters and stored timestamp conversion directly after treating them as untrusted persistence evidence. A throwing Proxy/accessor could therefore surface native dependency detail before the fixedPluginDeliveryAttemptPersistenceEvidenceErrorboundary.Reality regression
b390f37ed651ce2d9cb74d862fbae02641f3a55fcarries hostile SQL-result and row getters with a test-only sensitive sentinel and requires both to collapse to the fixed credential-free persistence evidence error. Minimum causal repaire9a8b212b24b4914069a48a113d118ff4e4c0a56adds one bounded evidence-read seam, snapshots SQL result/row evidence before semantic validation, and bounds storedDate.toISOString()conversion. It does not change SQL text, schema, admission identity, idempotency, retry budget or network authority.Exact proof head
ec2353a003c15c9f464b5d5d2454d3593427d768, run34213508199, job102019765395, completed GREEN on Ubuntu 24.04/PostgreSQL 16. The verifier first checked outb390f37...and reproduced one intended repository-test failure: the hostile getter's test sentinel escaped instead of the fixed evidence error. On the repaired exact head, canonical formatting and diff hygiene passed; the focused four-file delivery-attempt suite passed 24/24; Integration typecheck passed; and the complete Integration suite passed 403 tests with 3 environment-dependent skips across 65 files (63 passed, 2 skipped).CHANGELOG descendant
fe51a79c1e19cc7fb14e5296f04b3f91b41bf535then completed its own exact verifier run34213937828, job102021136219, GREEN across the RED replay, canonical formatting/diff hygiene, focused acceptance, Integration typecheck and the complete Integration suite. The later row-collection/revoked-evidence line advanced through permanent Integration-owned source and regression commits without copying sibling source. Its current bounded proof ise40fc9c60f122d7f3ed120075bfb07d273281711/ run35280418160SUCCESS; workflow-retirement descendante67fa3de97cde2331e2ea771b6150b84c0d986b1removes only.github/workflows/verify-plugin-delivery-attempt-row-collection.yml.Current parent adoption
#245 remains workflow-free exact
39ebec99d907356a99a1a15528a3a1df713472ed. This PR remains directly based on that exact #245 head and independent of mutable #250/#251 transport. Currente67fa3de...is an ordinary ahead-only descendant on the #252 lane; no parent source was copied, rewritten or force-pushed.Deliberate boundary
This slice admits durable attempts only. It does not claim worker execution, claim/lease, retry/backoff transitions, append-only sanitized outcomes, dead-letter/pause/resume, per-attempt revocation fencing, operator status, restart recovery, DNS resolution, redirect/proxy handling, outbound HTTPS, or provider credential use. A later executor must consume immutable released canonical egress authority for connect-time SSRF controls. Durable origin/delivery identity is not network authorization.
Keep Draft. The exact hostile-evidence and row-collection repairs plus their purpose-verifier retirements are complete, but current repository/security evidence, independent approval and stacked prerequisites remain required before normal integration. No merge/release claim, self-approval, bypass, force-push, destructive rebase, stale evidence reuse or gate weakening is made.
Refs #130, #205, #235, #244, #245, #250, #251; ContextualWisdomLab/.github#712.